ASOS confirms data breach after “HACKED” in-app notifications

by · BleepingComputer

UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment.

ASOS is a large UK-based online fashion retailer that sells clothing, footwear, accessories, and beauty products to customers worldwide, including in the United States.

ASOS has confirmed that third-party platforms used to communicate with customers were accessed without authorization and says basic personal information, including names and contact details, may have been exposed.

The company is now displaying an in-app notice telling customers to disregard the unauthorized push alert and not to click or engage with the external third-party link it contained.

Warning about notification now shown in ASOS app

However, the company has not confirmed the threat actor's claim that its Snowflake environment was compromised or disclosed how many customers may be affected.

ASOS says it does not believe payment-card information or account passwords were impacted.

If you have any information regarding this incident or other undisclosed attacks, you can contact us confidentially via Signal at 646-961-3731 or at tips@bleepingcomputer.com.

Hackers abuse ASOS mobile app

The notifications began appearing at approximately 5:00 a.m. ET on Tuesday, with multiple BleepingComputer readers contacting us after receiving the alerts on their phones.

"ASOS HACKED," reads the notification seen by BleepingComputer.

"Dear Asos DPO and IT, we have fully compromised the Snowflake instance. Engage with us, or we will leak it."

"ASOS HACKED" notification sent via the official ASOS mobile app
Source: Reddit

Numerous other ASOS customers also reported receiving the same notification on Reddit, indicating that the message reached many, if not all, mobile app users.

The notification directs ASOS to a Telegram channel operated by a threat actor calling itself the "Xuanye group."

In messages posted to the channel Tuesday morning, the threat actor claimed the breach did not affect payment information.

However, the attackers later published a "FINAL STATEMENT," claiming that they stole customer information in the attack.

"The affected organisation's app is safe to use. The incident involves customer information, it is safe on our server, and it will not be touched for a designated period," reads the group's message.

"Considering the current situation regarding incident disclosure in the cyber security landscape, you can thank us for our generous clarity regarding this incident."

The group did not disclose what customer information was allegedly stolen, how many customers were impacted, or provide evidence showing that it had compromised ASOS's Snowflake environment.

BleepingComputer attempted to contact the threat actors about the breach, but the only contact point required payment. We did not continue as it is against our editorial guidelines to pay for information.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

Save your seat